Check: GEN005000
SOLARIS 9 SPARC STIG:
GEN005000
(in version v1 r12)
Title
Anonymous FTP accounts must not have a functional shell. (Cat I impact)
Discussion
If an anonymous FTP account has been configured to use a functional shell, attackers could gain access to the shell if the account is compromised.
Check Content
Fix Text
Configure anonymous FTP accounts to use a non-functional shell. If necessary, edit the /etc/passwd file to remove any functioning shells associated with the FTP account and replace them with non-functioning shells, such as, /dev/null.
Additional Identifiers
Rule ID: SV-4387r2_rule
Vulnerability ID: V-4387
Group Title: GEN005000
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. |
Controls
Number | Title |
---|---|
AC-6 |
Least Privilege |